PT-2026-23458 · Unknown · Rustdesk Client

Erez Kalman

·

Published

2026-03-05

·

Updated

2026-03-05

·

CVE-2026-30793

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RustDesk Client versions through 1.4.5
Description A Cross-Site Request Forgery (CSRF) issue exists in RustDesk Client on Windows, MacOS, Linux, iOS, and Android. This flaw potentially allows for privilege escalation. The issue is related to the Flutter URI scheme handler and FFI bridge modules, specifically within the files flutter/lib/common.Dart and src/flutter ffi.Rs, and the routines URI handler for rustdesk://password() and bind.MainSetPermanentPassword().
Recommendations Update RustDesk Client to a version later than 1.4.5.

Exploit

Fix

LPE

Improper Authorization

CSRF

Weakness Enumeration

Related Identifiers

CVE-2026-30793

Affected Products

Rustdesk Client